Cosmic verification

slapd package on the consumer:
  Installed: 2.4.46+dfsg-5ubuntu1
  Candidate: 2.4.46+dfsg-5ubuntu1
  Version table:
 *** 2.4.46+dfsg-5ubuntu1 500
        500 http://br.archive.ubuntu.com/ubuntu cosmic/main amd64 Packages

Confirming failed replication attempt:
provider:
Nov 16 16:16:53 cosmic-provider slapd[2339]: conn=1004 fd=12 ACCEPT from 
IP=10.0.100.71:37472 (IP=0.0.0.0:389)
Nov 16 16:16:53 cosmic-provider slapd[2339]: conn=1004 op=0 UNBIND
Nov 16 16:16:53 cosmic-provider slapd[2339]: conn=1004 fd=12 closed

consumer:
Nov 16 16:16:53 cosmic-consumer slapd[2344]: slap_client_connect: 
URI=ldap://cosmic-provider.lxd ldap_sasl_interactive_bind_s failed (-2)
Nov 16 16:16:53 cosmic-consumer slapd[2344]: do_syncrepl: rid=001 rc -1 retrying

Host:
[sex nov 16 14:17:52 2018] audit: type=1400 audit(1542385073.436:831): 
apparmor="DENIED" operation="open" 
namespace="root//lxd-cosmic-consumer_<var-lib-lxd>" profile="/usr/sbin/slapd" 
name="/etc/krb5/user/110/client.keytab" pid=20151 comm="slapd" 
requested_mask="r" denied_mask="r" fsuid=165646 ouid=165536


Right after the consumer's openldap packages were updated, the provider logged 
this, showing that replication is working:
Nov 16 16:34:46 cosmic-provider slapd[2339]: conn=1022 fd=12 ACCEPT from 
IP=10.0.100.71:37582 (IP=0.0.0.0:389)
Nov 16 16:34:46 cosmic-provider slapd[2339]: conn=1022 op=0 BIND dn="" 
method=163
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=0 RESULT tag=97 
err=14 text=SASL(0): successful result: 
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=1 BIND dn="" 
method=163
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=1 RESULT tag=97 
err=14 text=SASL(0): successful result: 
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=2 BIND dn="" 
method=163
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=2 BIND 
authcid="consumer" authzid="consumer"
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=2 BIND 
dn="uid=consumer,cn=gssapi,cn=auth" mech=GSSAPI sasl_ssf=56 ssf=56
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=2 RESULT tag=97 err=0 
text=
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=3 SRCH base="dc=lxd" 
scope=2 deref=0 filter="(objectClass=*)"
Nov 16 16:34:51 cosmic-provider slapd[2339]: conn=1022 op=3 SRCH attr=* +


The consumer also has a tgt now in /tmp:
-rw-------  1 openldap openldap 1903 Nov 16 16:34 krb5cc_110


Consumer's packages:
root@cosmic-consumer:~# apt-cache policy slapd
slapd:
  Installed: 2.4.46+dfsg-5ubuntu1.1
  Candidate: 2.4.46+dfsg-5ubuntu1.1
  Version table:
 *** 2.4.46+dfsg-5ubuntu1.1 500
        500 http://br.archive.ubuntu.com/ubuntu cosmic-proposed/main amd64 
Packages


Cosmic verification succeeded.

** Tags removed: verification-needed-cosmic
** Tags added: verification-done-cosmic

-- 
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/1783183

Title:
  apparmor profile denied for kerberos client keytab and credential
  cache files

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/1783183/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs

Reply via email to